<?php

class UserAccessController extends Controller {

	/**
	 * @return array action filters
	 */
	public function filters() {
		return array(
			'accessControl', // perform access control for CRUD operations
		);
	}

	/**
	 * Specifies the access control rules.
	 * This method is used by the 'accessControl' filter.
	 * @return array access control rules
	 */
	public function accessRules() {
		return array(
			array(
				'allow',
				// allow admin user to perform 'admin' and 'delete' actions
				'actions' => array(
					'admin',
					'delete',
					'update',
					'view',
				),
				'roles' => array(
					'admin'
				),
			),
			array(
				'deny',
				// deny all users
				'users' => array(
					'*'
				),
			),
		);
	}

	/**
	 * Displays a particular model.
	 * @param integer $id the ID of the model to be displayed
	 */
	public function actionView($id) {
		$this->render('view', array(
				'model' => $this->loadModel($id),
			));
	}

	/**
	 * Updates a particular model.
	 * If update is successful, the browser will be redirected to the 'view' page.
	 * @param integer $id the ID of the model to be updated
	 */
	public function actionUpdate($userId = null, $id = null) {
		$model = null;
		if ($userId) {
			$model = UserAccess::model()->findByAttributes(array(
					'userId' => $userId
				));
		}
		if ($model === null)
			$model = $this->loadModel($id);

		// Uncomment the following line if AJAX validation is needed
		// $this->performAjaxValidation($model);

		if (isset($_POST['UserAccess'])) {
			$model->attributes = $_POST['UserAccess'];
			if ($model->save())
				$this->redirect(array(
						'admin',
					//'id' => $model->id
					));
		}

		$this->render('update', array(
				'model' => $model,
			));
	}

	/**
	 * Deletes a particular model.
	 * If deletion is successful, the browser will be redirected to the 'admin' page.
	 * @param integer $id the ID of the model to be deleted
	 */
	public function actionDelete($id) {
		if (Yii::app()->request->isPostRequest) {
			// we only allow deletion via POST request
			$this->loadModel($id)->delete();

			// if AJAX request (triggered by deletion via admin grid view), we should not redirect the browser
			if (!isset($_GET['ajax']))
				$this
					->redirect(
						isset($_POST['returnUrl']) ? $_POST['returnUrl']
							: array(
								'admin'
							));
		} else
			throw new CHttpException(400,
				'Invalid request. Please do not repeat this request again.');
	}

	/**
	 * Manages all models.
	 */
	public function actionAdmin() {
		$model = new UserAccess('search');
		$model->unsetAttributes(); // clear any default values
		if (isset($_GET['UserAccess']))
			$model->attributes = $_GET['UserAccess'];

		$this->render('admin', array(
				'model' => $model,
			));
	}

	/**
	 * Returns the data model based on the primary key given in the GET variable.
	 * If the data model is not found, an HTTP exception will be raised.
	 * @param integer the ID of the model to be loaded
	 */
	public function loadModel($id) {
		$model = UserAccess::model()->findByPk($id);
		if ($model === null)
			throw new CHttpException(404, 'The requested page does not exist.');
		return $model;
	}

	/**
	 * Performs the AJAX validation.
	 * @param CModel the model to be validated
	 */
	protected function performAjaxValidation($model) {
		if (isset($_POST['ajax']) && $_POST['ajax'] === 'user-access-form') {
			echo CActiveForm::validate($model);
			Yii::app()->end();
		}
	}
}
